Hackers Hijack HBO Max’s Reddit Account to Spread Crypto-Stealing Malware

CN
Decrypt
Follow
1 hour ago

Hackers hijacked streaming service HBO Max’s verified Reddit account earlier this month and used it to run 108 malicious advertisements over two days, cybersecurity experts warn.


In its report on Monday, researchers from cybercrime intelligence firm Hudson Rock link the account takeover to a broader operation targeting passwords and cryptocurrency wallet information.



Myriad: Who will be the top Spotify artist of 2026? Click to make your prediction.

“The incident was brought to light by Alex Cutts in the r/cybersecurity subreddit. While browsing the platform, they encountered an official Reddit advertisement authored by the verified u/hbomax account,” Hudson Rock wrote. “The ad aggressively promoted a native macOS application for HBO Max, a standalone application that does not currently exist.”


Instead of providing an installer, the site instructed visitors to open Terminal on a Mac, or Run or PowerShell on Windows, and paste a command that could infect their computer.


The technique, known as ClickFix, disguises malicious commands as routine steps for installing software, fixing errors, or proving a visitor is human. The hijacked account gave those instructions the apparent backing of a recognizable company.


Researchers dubbed the operation “PasteSwitch,” warning that its delivery system appears to adapt to the visitor’s device and the software being advertised.


Observed Mac payloads included MacSync and Atomic macOS (AMOS), information-stealer malware designed to steal sensitive information. Reported targets included browser credentials, Telegram data, Apple Notes, saved passwords, and cryptocurrency wallet recovery phrases.


“These clippers utilized Binance Smart Chain (BSC) contracts as mutable C2 dead drops,” researchers wrote, explaining that the malware checks Binance Smart Chain contracts for the latest address of the hackers’ control server. Hackers can then update that address when they switch servers, allowing the malware to keep finding them.


The broader operation was also linked to cryptocurrency clipboard hijackers, which replace a copied wallet address with one controlled by an attacker. A victim who pastes the substituted address without checking it could send funds to the wrong recipient. Stolen recovery phrases pose a separate risk because they can give attackers control of the associated wallet.


According to cybersecurity firm Malwarebytes, Reddit administrators paused the advertisements and opened a security investigation after receiving reports. The report did not establish how the account was compromised or how many people were infected. It described a Reddit account takeover, with no evidence presented of a breach of HBO Max’s streaming service.


ClickFix has appeared in other recent campaigns targeting cryptocurrency users. In August, researchers identified nearly 2,000 compromised WordPress websites supporting a malware operation that used fake verification prompts and could steal wallet information.


Microsoft researchers also described a separate campaign using fake CAPTCHAs to trick Windows users into running malicious commands, with instructions retrieved through BNB Chain.


免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink